CVE-2021-23012
- EPSS 0.19%
- Published 10.05.2021 15:15:07
- Last modified 21.11.2024 05:51:08
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow users granted either "Resource Administrator" or "A...
CVE-2021-23009
- EPSS 0.65%
- Published 10.05.2021 15:15:07
- Last modified 21.11.2024 05:51:08
On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Service for Data Plane traffic. TMM takes the configured HA action when the TMM process is aborted. There...
CVE-2021-23013
- EPSS 0.8%
- Published 10.05.2021 14:15:07
- Last modified 21.11.2024 05:51:09
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, the Traffic Management Microkernel (TMM) may stop responding when processing Stream Control Transmission Protoc...
CVE-2021-23011
- EPSS 0.65%
- Published 10.05.2021 14:15:07
- Last modified 21.11.2024 05:51:08
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.3, when the BIG-IP system is buffering packet fragments for reassembly, the Traffic Management Microk...
CVE-2021-23007
- EPSS 0.73%
- Published 31.03.2021 18:15:15
- Last modified 21.11.2024 05:51:08
On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclosed traffic, it may start dropping all fragmented IP traffic. Note: Software versions which have reached End of Software Development...
CVE-2021-22978
- EPSS 0.82%
- Published 12.02.2021 20:15:13
- Last modified 21.11.2024 05:51:03
On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12.1.x and 11.6.x versions, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete ...
CVE-2021-22977
- EPSS 0.65%
- Published 12.02.2021 20:15:13
- Last modified 21.11.2024 05:51:03
On BIG-IP version 16.0.0-16.0.1 and 14.1.2.4-14.1.3, cooperation between malicious HTTP client code and a malicious server may cause TMM to restart and generate a core file. Note: Software versions which have reached End of Software Development (EoSD...
CVE-2021-22981
- EPSS 0.23%
- Published 12.02.2021 18:15:12
- Last modified 21.11.2024 05:51:03
On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are v...
CVE-2021-22979
- EPSS 0.32%
- Published 12.02.2021 18:15:12
- Last modified 21.11.2024 05:51:03
On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12.1.x versions, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration util...
CVE-2021-22975
- EPSS 0.65%
- Published 12.02.2021 17:15:14
- Last modified 21.11.2024 05:51:03
On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, and 14.1.x before 14.1.3.1, under some circumstances, Traffic Management Microkernel (TMM) may restart on the BIG-IP system while passing large bursts of traffic. Note: Software versio...